Free Phishing Test
CISO

How Does UKSC/NIS2 Affect the CISO’s Role? A Digital Law Specialist and Attorney Answer

23-jun-2026 5 minutes read

KSC does not add new responsibilities to the CISO, but rather changes his role in the organization. Building digital resilience is something that mature companies have been doing for a long time – many of them have implemented security procedures, appointed responsible people, and systematically conducted tailored and realistic phishing simulations or organized cybersecurity training before the amendment appeared.

It is not a new technical obligation that raises the profile of the CISO role today, but the responsibility that has fallen on the management board. Amendment to the KSC Act, implementing the NIS2 directive, makes management personally responsible for cybersecurity.

We talked about what this change looks like in practice in a webinar with Marcin Serafin – a digital law specialist and partner of Sterberg law firm – and Jerzy Muszyński, a legal advisor who runs his own law firm. The conversation was moderated by Maciej Kołtoński, thanks to which there was also a business perspective. And if you want to watch the entire recording, fill out the form on this page.

What actually changes KSC in the CISO position?

KSC changes the position of the CISO – from a person performing technical tasks to a management partner who is personally responsible for cybersecurity.

So far, security has been treated as the subject of the IT department. The amendment shifts this burden higher, to the very top of the organization: it is the management who approves the risk analysis, provides the budget and is responsible for its own training, and delegating tasks to IT does not relieve it of its responsibility.

As legal advisor Jerzy Muszyński emphasized during the webinar:

For the first time, in such a broader context, we can talk about the fact that […] the company’s management board is to be an active entity participating in the ongoing management of cybersecurity within the company’s structures.
Jerzy Muszyński, legal advisor at SECAWA

The board needs a CISO as a risk translator

The management board, which is personally responsible for cybersecurity, necessarily must have someone who understands the risk, can manage it and translates it into decisions. It is from this relationship that the new position of CISO comes from.

Marcin Serafin described this mechanism directly:

When our management board members have their duties in terms of regular training, making decisions, and supervising the entire system of thinking about cybersecurity, they inevitably start to have to use someone who will explain this reality to them. Who will actually support them, and not just replace them.
Marcin Serafin, digital law specialist, partner of the Sterberg law firm

In other words: The CISO ceases to be a contractor, and becomes an advisor on whose analysis the management bases its own decisions – and its own responsibility.

CISO becomes an integral part of business

KSC 2.0 ends treating cybersecurity as a separate world, separated from business. Today, systems, data and tools are already a business – not an addition to it.

I hope that the problem of many CISOs who were left to themselves will end: do your own thing, tinker with your devices, analyze your reports, but don’t disturb our business. This is something that has to end – because this business is all about software and all these tools.
Marcin Serafin, digital law specialist, partner of the Sterberg law firm

For organizations, this means that security is no longer an incidental expense, but a condition for business continuity.

Not everyone is happy with this “promotion”

The growing importance of the CISO comes at a price – close, demanding cooperation with the management board. Not every specialist dreams of explaining risk to managers and sitting at the decision-making table. “This is a kind of increase in the importance of the CISO role within the organization (…). The CISO as a partner for the management is not left alone.” – said Marcin Serafin during webinar about KSC.

The advantage, however, is this: CISO stops working in a vacuum. He gains the support of the management board, but in return he has to spend more time explaining what exactly the threats are and how to solve them.

Why is there no single, universal definition of the CISO role?

A CISO in one organization is not the same as a CISO in another – these roles can be extremely different. The KSC clarifies the duties, but does not impose a single model for filling this position.

A CISO in an organization is not [equal to] another CISO in another organization. These roles are indeed extremely different.
Marcin Serafin, digital law specialist, partner of the Sterberg law firm

The differences in the CISO role concern resources, independence and the right to make decisions – some act independently, others are dependent on the management at every step.

Implication for the decision maker: Before filling this role, the board must decide the scope of authority, budget and independence of the CISO.

What does KSC mean in practice – for the management board and for CISO

Real change occurs when the CISO gets access to the management board, a budget and the right to make decisions – not just a title.

In practice, this means three things:

for the management board: training, social-engineering tests and penetration testing, approving risk analysis and security budget is an obligation, not a gesture of good will,
for CISO: more time to translate the risk in the language of business than on the risk itself tools
for the organization: clear path, who receives the decision and who is responsible for it.

Summary

The new position of CISO comes from the responsibility that KSC has placed on the management board.

This is a change that both parties can benefit from:

  • The management board receives an advisor who translates the risk into the language of decisions,
  • CISO – real influence, close cooperation with the management board, greater decision-making and leaving the role of a person detached from the business and being an integral part of it.

There is one condition: the CISO role must be given resources, budget and the right to make decisions.

The entire conversation – with specific examples, implementation schedule and question session is available on request. Sign up and you will receive access to the webinar recording and a set of materials (presentation and UKSC/NIS2 validator).

Free webinar. How to approach the implementation of KSC sensibly: so as not to take on everything at once, but also to complete the duties on time.

Gain specialised knowledge about cybersecurity

Build a resilient cybersecurity culture with our support

Let's discuss your organization's cyber needs

Fill in the form

Would you like to test the resilience of your systems?

Fill in the form to schedule a free, no-obligation consultation. We will discuss the scope of the penetration tests and prepare a proposed approach tailored to your organization and infrastructure.
Would you prefer to speak to us directly?
+48 732 123 579